Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-08-07
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Server Administrator software prior to version 11.1.0.2 contains an Improper Authentication weakness. An attacker who can reach the remote management interface may log in without valid credentials, enabling them to carry out administrative actions on the host.

Affected Systems

The vulnerability affects Dell OpenManage Server Administrator Managed Node on several platforms: RHEL 8.10, RHEL 9.4, SLES 15, and a patched Windows Managed Node version. Only installations running a version earlier than 11.1.0.2 are impacted; later releases include the fix.

Risk and Exploitability

With a CVSS score of 7.7, the risk is considered high. The description states that an unauthenticated attacker can reach the remote service, implying a network‑based, remote attack vector. EPSS data is not available, and the vulnerability is not yet listed in CISA's KEV catalog, reducing confidence in active exploitation but still indicating a serious potential. Organisations that expose OMSA to external networks or have inadequate network segmentation face a clear pathway for unauthorized access.

Generated by OpenCVE AI on August 7, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Server Administrator to version 11.1.0.2 or newer on all affected hosts.
  • If a patch cannot be applied immediately, block incoming traffic to the OMSA management port from untrusted networks using firewall rules or network segmentation.
  • Enable strong authentication mechanisms and regularly review user access privileges in OMSA to reduce the impact of any potential credential compromise.

Generated by OpenCVE AI on August 7, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 07 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Remote Access via Improper Authentication in Dell OpenManage Server Administrator

Fri, 07 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-08T03:55:28.341Z

Reserved: 2026-06-23T05:04:35.872Z

Link: CVE-2026-56793

cve-icon Vulnrichment

Updated: 2026-08-07T13:15:59.159Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-07T13:16:52.503

Modified: 2026-08-08T05:17:09.880

Link: CVE-2026-56793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:41:07Z

Weaknesses